- State
- IL
- Covered entity type
- Healthcare Provider
- Individuals affected
- 10,000
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On August 21, 2015, an unknown entity hacked into the covered entity's (CE) electronic database utilizing a Crypto Locker computer virus, and the virus attached to some of the CE's Portable Document Format (PDF) files which contained patients’ names, dates of birth, clinical information, and other personal identifiers. The virus then blocked the CE's access to the aforementioned PDF files and the CE received an email message demanding a $500.00 ransom in order to gain access to the locked PDF files. Approximately 10,000 individuals were affected by the breach. Upon discovering the breach, the CE conducted a breach risk assessment which indicated that there was a low overall probability that protected health information (PHI) was compromised, and therefore, breach notification to individuals and the media was not required. The CE reported the breach incident to the Internet Crime Complaint Center, a division of the Federal Bureau of Investigations. To prevent similar breaches from happening in the future, the CE retained a computer forensic firm to assist with the analysis of the ransomware incident, and installed anti-malware products on all its computers. The CE trained staff on its policies and procedures regarding Cyber Security Awareness. OCR obtained documented assurances that the CE implemented the corrective actions noted above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.